Between Elequate LLC, 5333 N 7th St B114, Phoenix, AZ 85014 ("Elequate") and the client that enters into a services agreement with us ("you"), covering how we handle your data while you're live on our platform.

1. What this covers

This agreement is posted at elequate.io/dpa and forms part of our services agreement with you. Where the two conflict on how your data is handled, this one controls; on everything else, the services agreement controls. No purchase order, statement of work, vendor-portal or supplier-registration term, click-through, security or privacy addendum, or questionnaire response amends either of them.

Your data is what you put into our platform and what you authorize us to pull in for you — CRM records, contacts, leads, transactions, calendar and activity data, call recordings and transcripts, and agent performance data. Personal information is the part of it that identifies, relates to, describes, or could reasonably be linked to a person or a household. Aggregated and de-identified data is neither personal information nor your data; Section 11 governs it.

Updates. We may update this agreement by posting a new version at elequate.io/dpa. A change that materially reduces your rights takes effect at your next renewal; anything else takes effect when posted. We decide which changes are material.

2. Our roles

You decide why and how your data gets processed. We process it for you. In the language the privacy statutes use, you're the controller — the business under California law — and we're the processor, your service provider.

You're responsible for having a lawful basis to collect and use your data, for giving your agents and consumers the privacy notices the law requires, and for honoring the rights and choices those people exercise.

Our certification. We certify that we understand the following restrictions and will comply with them. We won't sell or share your personal information, as those words are defined under California law. We won't retain, use, or disclose it for any purpose other than the business purposes in Section 3, including outside our direct business relationship with you. We won't combine it with personal information we receive from or about anyone else, except as a service provider is expressly permitted to. We'll give it the level of privacy protection the law requires of you. If we ever determine we can no longer meet our obligations under privacy law, we'll tell you, and you can direct us to stop and remediate any unauthorized use. You can take reasonable steps to confirm we're meeting these commitments, using Section 8.

Nothing here is a sale, license, or transfer of personal information to us for value, and no part of what you pay us is consideration for personal information.

3. What we do with your data

We process your data only on your documented instructions. Our services agreement, this agreement, your configuration choices in the platform, and your ordinary use of the services are your complete documented instructions. Anything beyond that has to be agreed in writing, and may be billable.

Why we process it. To provide, operate, host, secure, and support the platform; to run the integrations you authorize; to generate the dashboards, reporting, scoring, call intelligence, coaching insight, and analysis we deliver to you; to detect and prevent fraud, abuse, and security incidents; to debug defects and maintain the quality of the services; and to do what Section 11 allows.

What you authorize us to connect to. Your CRM — Follow Up Boss, Sierra, kvCORE, Lofty, or whatever you run — your phone and call-recording systems, your calendar and scheduling tools, your transaction and production records, spreadsheets and file exports, and any other system or file that holds your business data, by API key, OAuth, file export, or any method you enable. Delivering the services requires us to copy, store, transmit, host, transform, normalize, index, transcribe, enrich, model, and analyze your data, and you authorize all of it for the purposes above.

Your authority. You represent and warrant that you can grant this access; that it doesn't violate any agreement with a third party, including your CRM, phone provider, brokerage, or MLS; that you've given every notice and obtained every consent privacy law requires for us to receive and process this data, including information about your leads, customers, and agents; that what you send us is lawfully yours to send and accurate as far as you know; that you'll honor the consumer rights and opt-outs you receive; that you'll keep your agents' credentials confidential and tell us promptly when someone's access should end; and that compliance in every state your consumers live in is yours. If any of that turns out not to be the case, you'll defend, indemnify, and hold Elequate harmless from any resulting third-party claim, penalty, fine, or liability, and from any fine, penalty, assessment, or direct loss we incur as a result, whether or not a third party brings a claim.

If an instruction appears unlawful. If we reasonably believe something you've told us to do violates privacy law, we'll tell you, and we can pause that processing until you withdraw, amend, or confirm the instruction.

4. Your data stays yours; our findings stay ours

You own your data. We claim no ownership of it. We won't sell, rent, or lease it, make it available to anyone for money or other value, use it for targeted or cross-context behavioral advertising, or give it to an ad network or a data broker, and we won't disclose identifiable data about you to another client of ours. Aggregated data and derived assets under Section 11 aren't your data, and this paragraph doesn't reach them.

Your source data never leaves you. Everything we receive is a copy. The originals stay in your CRM, your phone system, and your own files throughout, and nothing here or in our services agreement changes that.

Our findings are our work product. We own our platform, its software, our scoring frameworks, methodology, rubrics, models, benchmarks, and know-how, and everything Section 11 covers. The scores, classifications, analyses, benchmarks, assessments, rankings, and other outputs the platform generates are ours, and running them on your data doesn't transfer, share, or license them to you. While our services agreement is in force, the reports and dashboards we prepare are yours to use inside your company, to the extent they show your data and your results. They aren't available for export, and they don't survive the end of your access.

5. Security

We'll use commercially reasonable, industry-standard administrative, technical, and physical safeguards to protect your data from unauthorized access, use, disclosure, alteration, or loss, appropriate to the size of our operations and the nature of the data. We can change our controls over time, as long as we don't materially reduce the overall level of protection during the term. Access to your data is limited to the people who need it to do the work, and everyone we bring in — employee or contractor — is bound by confidentiality obligations that outlast their engagement.

Tenant separation. Your data is logically separated by client and team identifier inside shared infrastructure, applied in our application logic and query layer. Separation is not enforced at the database engine level, and we make no claim of physical or dedicated-instance isolation.

Encryption. Your data is encrypted in transit with industry-standard transport encryption, and at rest using the encryption our hosting and storage providers give us. Those providers manage the keys, and we don't offer customer-managed or client-held keys.

AI and machine learning. We use third-party AI and machine-learning providers for transcription, classification, scoring, and analysis. We'll use commercially reasonable efforts to select providers that don't train their general-purpose models on customer content, and to enable any setting or contract term that says so. We can't guarantee it — we don't control their internal practices. None of this limits our own rights under Section 11.

What we don't have. We don't hold — and aren't currently pursuing — a SOC 1 or SOC 2 report of any type, ISO/IEC 27001 certification, a PCI DSS attestation, or HITRUST certification, and you're not relying on any such certification in signing our services agreement. We also don't represent that we maintain point-in-time recovery or any recovery objective, any uptime or performance service level, scheduled third-party penetration testing, around-the-clock security monitoring, a certified information security management system, criminal background screening, a recurring security-awareness training program, or cyber liability, technology errors and omissions, or data breach insurance. If we later earn a certification or add a control, we may say so, and saying so doesn't amend this agreement.

Neither of us can promise any system is perfectly secure, and we don't warrant that your data will never be subject to unauthorized access.

6. Our vendors and where your data goes

We run our platform on established third-party infrastructure. The categories of vendor that process your data are in Section 15.

We may share your data with them as needed to do the work. We engage each under a written contract that requires it to meet the obligations that apply to us under this agreement with respect to your personal information, to the extent those obligations are relevant to what the vendor does for us, and we stay responsible to you for what they do with your data. We don't inspect, audit, test, or warrant any vendor's internal security practices, and you're not relying on us to. Beyond those providers we don't share your data with anyone, except where a court or regulator compels it or this agreement is assigned under Section 13.

Changing vendors. We add and replace vendors as the platform changes. The version of Section 15 posted at elequate.io/dpa is the current list, and posting it is the only notice we owe you. If a change materially affects the protection of your personal information, your remedy is to terminate the affected services on written notice, and it's your only one. A vendor change doesn't need your approval and doesn't wait on your objection.

Where processing happens. Your data is processed in the United States, and some of our vendors may process or store it elsewhere. We don't guarantee data residency in any country, region, or facility.

Government demands. If a government authority serves us with a legally binding demand for your data, we'll tell you before we disclose anything where the law lets us, disclose only what's legally required, and try to redirect the request to you.

7. Security incidents

A security incident is a confirmed breach of our security, or of a vendor's under Section 6, that leads to unauthorized access to, acquisition of, or disclosure of your data in our possession or control or theirs. Unsuccessful attempts, pings, scans, and routine failed logins aren't security incidents.

We'll tell you about a security incident without undue delay after we become aware of it. That commitment runs from our actual awareness — we don't operate around-the-clock monitoring and we don't commit to a fixed number of hours. We'll tell you what we reasonably know at the time and supplement as we learn more, take reasonable steps to contain and remediate the incident, and reasonably cooperate with your investigation and your own notification obligations.

You notify your people. Deciding whether a regulator, consumer, or anyone else has to be notified, and doing it, is yours. We won't notify your consumers or regulators on your behalf without your written direction, unless the law independently requires us to. Our notice and our remediation aren't an admission of fault or liability.

8. Checking our work

Once in any twelve-month period, on thirty days' written notice, you can ask us to verify in writing that we're meeting our obligations under this agreement. We'll respond within a reasonable time, at your own cost, and at our option we'll do it by completing a reasonable written security questionnaire or by giving you a written summary of our security practices. Excessive or repetitive requests are billable.

What this doesn't include. It doesn't include, and you won't request: on-site inspection; access to our systems, networks, production environment, administrative consoles, source code, or logs; access to any other client's data; interviews of our people beyond reasonable written answers; scanning, probing, or penetration testing of our systems or our vendors'; or any audit conducted by a competitor of ours. What we give you is our confidential information, can be used only to verify our compliance with this agreement, and can't go to anyone else without our written consent — your professional advisors under confidentiality excepted. If a regulator with jurisdiction over you needs more, we'll cooperate in good faith, at your expense, in the least burdensome way available.

9. Consumer requests

You receive, verify, and respond to requests from consumers and agents exercising their rights — access, deletion, correction, portability, opt-out. Taking into account the nature of the processing and what's available to us, we'll give you reasonable assistance on a verified written request from you. Ordinary-course assistance is free; volume or complexity beyond the ordinary course is billable. Send requests with enough lead time for us to help — we don't commit to a turnaround, and meeting your statutory deadline is yours.

If a consumer or agent comes to us directly, we won't answer substantively. We'll point them to you and tell you, unless the law says we can't. We act only on your instructions, and we're entitled to rely on your verification of who's asking and what they're entitled to.

Deletions. On your verified written instruction, we'll delete or de-identify the identified personal information in our production systems within a reasonable time. That doesn't reach what Section 11 covers, data sitting in routine backup or disaster-recovery media awaiting its scheduled expiry, or records we're required to keep by law, regulation, or legal hold. We're not required to reconstruct, re-derive, or retrain anything.

These are individual rights under privacy law, exercised by the person they belong to. They give you no right to an export of your data or of anything the platform produces; Section 4 governs that.

10. What you send us

Call recordings. If your systems make call recordings available, we'll ingest and analyze them. Elequate doesn't place or record them — we process only what your systems hand us. You represent and warrant that for every recording you make available, and for as long as this agreement runs, you've obtained every consent and given every disclosure federal and state law requires, including all-party consent wherever any state involved requires it. You acknowledge that some states require every party on a call to consent, that your agents may be calling people in other states, and that the rule can follow wherever the other person is. Whether a recording was lawfully made is your responsibility alone. If it wasn't, you'll defend, indemnify, and hold Elequate harmless from any resulting third-party claim, penalty, fine, or liability. This survives termination. You can tell us in writing to stop ingesting recordings at any time; that will materially limit the call intelligence features, and it doesn't reduce your fees.

What you can't send us. The platform isn't designed, tested, or contractually suited to receive the following, and you won't submit them or configure any integration that transmits them:

Call recordings and transcripts are permitted; what's prohibited is a biometric voiceprint template used to identify a person.

If you send restricted data anyway, you're in breach. We can delete or quarantine it without notice and without liability, we owe it no heightened standard of care, and you'll defend, indemnify, and hold Elequate harmless from any claim arising from it. Our receiving, storing, or processing restricted data — whether or not we notice it — doesn't waive this section, expand what we owe you, or make us a business associate, a financial institution, or a regulated entity under any statute.

11. Aggregated data and cross-client research

This section is a material inducement to our entering the services agreement and is priced into the fees.

Aggregated data means data derived from your data that's been aggregated with other data, or had direct and indirect identifiers removed or obscured, so it can't reasonably be used — alone or with anything else reasonably available to us — to identify or link to you, any agent, any consumer, or any other person or household. Derived assets means aggregated data and everything we build from it or informed by it: statistics, rates, and distributions; benchmarks, indices, baselines, percentiles, and comparison sets; scores, scoring frameworks, rubrics, taxonomies, and classification schemes; models, weights, parameters, embeddings, prompts, evaluation sets, and algorithms; research findings, studies, analyses, and reports; and methodologies, techniques, improvements, and learnings.

What we own. We own all right, title, and interest in aggregated data and every derived asset. We may create, derive, retain, reproduce, modify, disclose, publish, license, sell, commercialize, and otherwise use them — at any time, during and after the term, as an ordinary and continuous part of running the platform — for any purpose, without limitation of purpose, scope, territory, or time, and with no fee, royalty, accounting, attribution, or further consent owed to you. These rights survive termination or expiration of this agreement and the services agreement, and they survive any deletion or destruction of your data.

Cross-client research. We may combine, pool, and jointly analyze data derived from your data together with data derived from other clients, from our own operations, and from third-party and public sources, to run research, studies, benchmarking, analysis, and model development across our whole client base. We may design, run, publish, and commercialize those studies, and everything that comes out of them is exclusively ours, subject only to the limits below. The data stays yours; the findings are ours.

Aggregation comes first. We aggregate or de-identify data derived from your data before we pool it with anything from another client or any other source, so what gets pooled isn't personal information. We don't use personal information to build or modify a profile about a consumer, or to correct or augment data we got from somewhere else. If any of this is ever held to conflict with our certification in Section 2, that certification controls as to personal information only, and the rest of this section stays in full force as to aggregated data and derived assets.

How we de-identify. We take reasonable measures to make sure the data can't be associated with, or reasonably linked to, a consumer, household, agent, or client, directly or indirectly. We publicly commit to maintain and use it in de-identified form and not to attempt to re-identify it, except to test whether our own de-identification works — and we delete that test data promptly. And we contractually obligate anyone we give it to to do the same and to pass those obligations down.

Minimum cohort. We won't externally publish or distribute any statistic, benchmark, or finding derived from fewer than [MINIMUM COHORT SIZE] distinct clients or teams, and we'll suppress, combine, or round anything that would otherwise make a single client, team, agent, or consumer reasonably identifiable — including through combination with geography, market size, brokerage, or timing.

Attribution. We won't publish or externally distribute anything that names you or is reasonably attributable to you without your written consent. Subject to that and to the minimum cohort rule, our internal use and our use of pooled, anonymized, multi-client results is unrestricted.

Hard limits. Nothing in this section lets us sell your data, disclose personal information or identifiable data about you to anyone other than a vendor under Section 6 or as the law requires, or attempt — or let anyone we share with attempt — to re-identify any person, household, agent, or client.

Nothing erodes this. These rights override any term that would cut them down, wherever it sits: another agreement between us, a confidentiality or return-or-destruction provision, a policy, purchase order, vendor-portal term, click-through, addendum, questionnaire response, or course of dealing. No term limiting, conditioning, or terminating them binds us unless it's a written amendment to this agreement, signed by an authorized officer of Elequate, that names this section by number and title. Aggregated data and derived assets are excluded from every deletion and destruction obligation either of us has, including a consumer deletion request under Section 9.

12. Retention and deletion

We keep your data while our services agreement is in force and for as long as we need it for the purposes in Section 3. We haven't adopted a retention schedule, and this agreement doesn't set one.

No return obligation. Your source data stays in your own systems throughout, and what we produce on top of it is our work product under Section 4. This agreement gives you no right to an export of your data or of anything the platform generates, and access to reports and dashboards ends when your access does.

Deletion. After the services agreement ends, ask us in writing and we'll delete your data. That doesn't reach aggregated data and derived assets under Section 11, which are permanently excluded; data in routine automated backup or disaster-recovery media awaiting its scheduled expiry, which stays confidential until it's gone; or records we're required to keep by law, regulation, or legal hold, until the hold lifts. On request we'll confirm in writing once we've done what this section requires, and we won't certify the deletion of anything in that list.

A deletion request while the services agreement is still in force is a request to discontinue the affected services. It doesn't reduce your fees, and we're not in breach for anything we can't deliver without that data.

Any earlier NDA. A return-or-destruction provision in a non-disclosure agreement we signed before this one doesn't require us to give up data we hold in order to run the services, and doesn't restrict any use this agreement permits. From the effective date of our services agreement forward, this section governs retention and deletion.

13. General terms

Term and survival. This takes effect on the effective date of our services agreement and runs for as long as we process your data, whether or not the services agreement is still in force. Sections 4, 10, 11, 12, and this Section 13 survive termination or expiration for any reason, and Sections 2 and 5 through 9 survive for as long as we still hold your data. Termination of the services agreement for any reason — including termination by you for our breach — doesn't reduce, revoke, or condition anything reserved to us in Section 11.

What doesn't bind us. A questionnaire response, checkbox, vendor-portal entry, supplier-registration term, click-through, or security addendum submitted by us or on our behalf is informational convenience only — including one that asserts a certification, control, insurance, or commitment we don't hold. It creates no obligation, representation, or warranty, and you won't treat it as a contractual commitment.

Notices. Anything requiring writing can go to the addresses in our services agreement, to [email protected], or to the business email each of us normally uses with the other. Email counts.

Equitable relief. If either of us breaches — or is about to breach — the confidentiality or intellectual-property terms here, money alone wouldn't fix it and the harm would be irreparable. The other can seek an injunction or other equitable relief on top of any other remedy, and will ask the court to set the smallest bond it may require. On a claim under Section 10 or Section 11, the prevailing party recovers its reasonable attorney's fees and costs.

Liability. The limitations and exclusions of liability in our services agreement apply to this agreement and to any claim arising from the processing of your data, except where privacy law makes them unenforceable. If no services agreement is in force between us, those same limitations still apply, as if it were. They don't reduce your indemnities in Sections 3 and 10. Whoever's being covered under one of those indemnities will say so promptly, let the other run the defense, and cooperate at the other's expense.

Everything else. Neither of us grants the other any license or ownership beyond what's written here. Neither may assign this agreement without the other's written consent, except to a successor in a merger or sale of substantially all assets, and our rights under Section 11 are assignable with the business. An unenforceable provision is narrowed only as far as needed and the rest stays in force — and as to Section 11, narrowed to preserve the broadest grant of rights to Elequate the law allows. Not enforcing something right away doesn't waive the right to enforce it later. This agreement creates no third-party beneficiary rights. Florida law governs, and any dispute will be brought only in the state or federal courts in Miami-Dade County, Florida — each of us consents to their jurisdiction, waives any objection to venue, and waives any right to a jury trial. We update this agreement under Section 1; a change you ask for takes a written amendment signed by both of us, and an amendment affecting Section 11 also needs an authorized officer of Elequate to sign it and must name that section. It may be signed electronically and in counterparts.

14. Details of processing

Item Detail
Subject matter Our provision of the platform and any programs to you under the services agreement.
Duration The term of the services agreement, plus the deletion period in Section 12. Aggregated data and derived assets are kept indefinitely under Section 11.
Nature of processing Ingestion from your connected systems; storage and hosting; normalization and indexing; transcription of call recordings; classification, scoring, and analysis, including by AI and machine-learning providers; generation of dashboards, reports, and coaching insight; aggregation and de-identification; deletion.
Purpose The business purposes in Section 3.
Frequency Continuous or scheduled synchronization for the duration of the term.
Data subjects Your agents, inside sales agents, team leaders, and staff; and the prospective and actual buyers, sellers, and other consumers your team interacts with.
Data about your people Name, business email and phone, role, team assignment, credentials and login activity, activity and productivity metrics, call and appointment counts, pipeline and transaction attribution, scoring and coaching results, program enrollment, and recordings and transcripts of practice sessions.
Data about your market Name, email, phone, mailing and property address, lead source and campaign, CRM stage and status, agent notes and tags, call metadata, call recordings and transcripts, appointment data, and transaction and closing data.
Sensitive categories None permitted — see Section 10. Recordings and transcripts may incidentally contain whatever a consumer volunteers on a call.
Location Primarily the United States; some vendors may process or store data elsewhere. No residency guarantee — see Section 6.

15. Vendor categories

These are the categories of vendor that process your data, and the provider we currently use in each. We update this list under Section 6.

Note: The named provider in each category is being finalized and will be posted here.

Category What it does Vendor
Cloud hosting and compute Runs the platform and its APIs [VENDOR NAME]
Managed database and object storage Stores your data, files, and media [VENDOR NAME]
Edge network, CDN, and DNS Delivery, caching, routing, WAF and DDoS protection [VENDOR NAME]
AI and machine learning Transcription, classification, scoring, analysis [VENDOR NAME]
Speech and voice processing Practice and roleplay tools [VENDOR NAME]
Telephony and media storage Call recordings and metadata [VENDOR NAME]
CRM and business-system integrations Retrieving data from the systems you authorize [VENDOR NAME]
Video conferencing and meeting recording Coaching and 1:1 recordings, where you enable it [VENDOR NAME]
Transactional email delivery Platform notifications, reports, account email [VENDOR NAME]
Product analytics and error monitoring Defect diagnosis and platform health [VENDOR NAME]
Payment processing Billing you — your billing contact data, not consumer data [VENDOR NAME]
Business productivity and support tooling Internal collaboration and support ticketing [VENDOR NAME]

16. Signatures

This agreement is normally accepted by reference in our services agreement and doesn't need a separate signature. Where you'd rather sign it, a signed counterpart has the same effect — ask us for one.

By signing a counterpart, each of us confirms we've read this agreement, agree to be bound by it, and that whoever signs has the authority to bind the organization they're signing for. It takes effect on the effective date of our services agreement.

Contact Us

If you have questions about this agreement, please contact us:

Elequate LLC
5333 N 7th St B114, Phoenix, AZ 85014
Email: [email protected]